📦

0852-1505\/000-001

Vendor: wago

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 6 Total Indexed
Avg. EPSS 0.81% Exploit Prob.
Latest CVE CVE-2021-20998 May 13

Security Vulnerability Index

Page 1 / 1
10.0 CVSS

In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users.

EPSS: 1.11%
7.5 CVSS

In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users.

EPSS: 1.02%
5.3 CVSS

In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties.

EPSS: 0.75%
5.3 CVSS

In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials.

EPSS: 0.54%
8.8 CVSS

In multiple managed switches by WAGO in different versions an attacker may trick a legitimate user to click a link to inject possible malicious code into the Web-Based Management.

EPSS: 0.63%
5.3 CVSS

In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory.

EPSS: 0.79%